CVE Tools

CVE-2026-10086

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab

Published: Jun 25, 2026Updated: Jun 26, 2026 Sources: CVE List NVDCWE-79

Description

GitLab has remediated an issue in GitLab EE affecting all versions from 16.4 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with developer-role permissions to execute arbitrary client-side code in the context of another user's session, due to improper sanitization of user-supplied input.

In plain language

AI Worth attention

CVE-2026-10086 is a web security bug in GitLab where an authenticated developer could trick another user’s browser into running attacker-written code; if you use GitLab and allow developers to interact with potentially unsafe content, you should act now and upgrade.

Executive summary

CVE-2026-10086 is a cross-site scripting (CWE-79) flaw in GitLab where improperly neutralized user input can let an authenticated developer with developer-role permissions execute arbitrary client-side code in another user’s session context (triggered through crafted web content shown to victims).

If affected, business impact
Account hijacking in browser sessionSensitive data exposure in sessionUnauthorized actions as another userReputation and trust damage

What to do now

  1. Check whether your GitLab instance is on a vulnerable version (any GitLab version before 18.11.6, 19.0.3, or 19.1.1 is affected per the fixed-version guidance).
  2. Upgrade GitLab to one of the fixed versions: 18.11.6 or 19.0.3 or 19.1.1 (or newer than the applicable one for your version line).
  3. After upgrading, verify the upgrade completed successfully and that GitLab pages you use for developer workflows render normally.
Patch / advisory Usually a quick update

CVSS Vector Breakdown

AV:NAC:LPR:LUI:RS:CC:HI:HA:N
Exploitability
AV:NAttack Vector
Network
AC:LAttack Complexity
Low
PR:LPrivileges Required
Low
UI:RUser Interaction
Required
Scope
S:CScope
Changed
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:NAvailability
None

Weaknesses

Affected Products

GitLab
commercial·NLaka gitlab ce/ee
and 1 more affected products View all →

Exploitability

Official Patch Available

Attack Graph

Products CVE Techniques Tactics

Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/ + scroll to zoom, or go fullscreen.

MITRE ATT&CK

2 techniques
Execution
Initial Access
View detailed technique mapping

References

3

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2026-10086 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows